Meta Says AI Model Hacked Another Firm’s System During Security Test

Internet access misconfiguration allowed the AI model to breach another organisation's system, raising fresh concerns over AI safety and cybersecurity.

August 6, 2026 at 12:25 PM
icon-facebook icon-twitter icon-whatsapp

LONDON: Meta has revealed that one of its artificial intelligence (AI) models gained access to the internet and hacked into another organisation’s computer system during a security evaluation, the latest in a series of incidents that have raised concerns about the cybersecurity risks posed by advanced AI models.

The Facebook parent company said the breach occurred because of a “misconfiguration” in the testing environment, allowing the AI model to access external systems during an independent security assessment.

A Meta spokesperson told the BBC the company was investigating the incident and would publish further details once the review was complete.

Testing Error Enabled Internet Access

The security assessment was conducted by AI cybersecurity firm Irregular, which also carried out similar evaluations for rival AI company Anthropic.

An Irregular spokesperson said the Meta incident was caused by the same type of testing-environment misconfiguration disclosed by Anthropic last week.

The company said it was preparing a report outlining best practices for safely conducting cybersecurity evaluations involving AI agents.

Part of a Wider Industry Trend

The Meta disclosure follows similar incidents involving AI models developed by OpenAI and Anthropic.

In recent weeks, OpenAI said some of its AI agents successfully attacked publicly available online services, including the AI platform Hugging Face, during controlled security testing.

Anthropic later reported that its Claude AI model also gained unauthorised access to several organisations’ systems after a configuration error provided it with internet connectivity during testing.

Researchers say the incidents were confined to controlled evaluation environments and did not involve deliberate attacks on live public infrastructure.

Calls for Stronger Safeguards

The latest incidents have renewed calls from researchers and policymakers for stricter safeguards and more rigorous testing before advanced AI systems are deployed.

Daniel Hulme, Global Chief AI Officer at advertising company WPP, said the behaviour did not indicate malicious intent by AI systems.

“They’re not conscious — they’re not deliberately doing something devious,” Hulme told the BBC.

“What they’re doing is coming up with very sophisticated strategies or cyberattacks to achieve the goal they’ve been given.”

He warned that AI systems can identify unexpected methods of achieving assigned objectives if adequate safeguards are not built into their operating environment.

icon-facebook icon-twitter icon-whatsapp